Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Hugo_vd_Kooij
MVP Gold
MVP Gold

How to get a smarter log?

Here is my puzzle I have with a customer.

We incresed security by switching IPS from detect to prevent.

We noticed a lot of DETEC log entries and were going over the steps to make sure we didn't miss anything. And everything is as it should be.

Then I did track the specific source and reviewed the logs and found the reason.

If another blade (FW or VPN) drops the packet/connection then IPS only logs a DETECT as another blade did the blocking action. So now I would very much like to see if there is a simple way to get the details from the DETECT log entry and then open a second log tab with a filter based on the Source IP and destination IP of the DETECT log line I am investigating.

Anyone with a suggestion in this regard?

<< We make miracles happen while you wait. The impossible jobs take just a wee bit longer. >>
0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events